Skip to content

qrcode uses an outdated version or yargs with a vulnerable transitive dependency #374

@davidsyckle

Description

@davidsyckle

qrcode uses a direct dependency ("yargs": "^15.3.1") that pulls in a vulnerable component (y18n@4.0.3). Please update yargs to 17.0.2 or newer to remediate this issue. :)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions